ZeroHour
Vendor

Grav CMS

2 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

Extortion group ShinyHunters hacked the Clop ransomware gang's leak site, defacing it and stealing server data and onion service private keys.

ShinyHunters breached the Clop (Cl0p) ransomware operation's Tor data leak site on Friday night, defacing it and allegedly stealing server data plus the private keys for its onion service. The attackers claim they exploited an unauthenticated file upload vulnerability in Grav CMS. ShinyHunters is reportedly threatening to extort the ransomware gang itself.

DataBreaches.net · 12h agoData breach in the wild 5 sources

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

ShinyHunters exploited a Grav CMS file upload flaw to breach and deface the Clop ransomware gang's leak site, claiming theft of source code, logs, and Tor private keys.

The ShinyHunters extortion gang exploited a claimed unauthenticated file upload vulnerability in Grav CMS to upload a taunting file and completely deface the Clop ransomware operation's Tor data leak site with Umbreon ASCII art. ShinyHunters claims it gained full server access, stealing source code, Grav CMS plugins, /var/log files, and the private keys for Clop's onion service, and plans to extort Clop with a 72-hour deadline. The feud reportedly stems from Clop's 2025 Oracle E-Business Suite extortion campaign, which used the zero-day CVE-2025-61882 and an exploit ShinyHunters says was stolen from them. BleepingComputer confirmed the defacement but could not verify the data theft or key theft claims.

BleepingComputerupdated · 12h agofirst · 12h agoRansomware in the wild 5 sourcesCVE-2025-61882

[webapps] Grav CMS 2.0.7 - RCE

A proof-of-concept exploit for remote code execution in Grav CMS 2.0.7 has been published on Exploit-DB.

Exploit-DB lists a public proof-of-concept exploit for a remote code execution vulnerability in Grav CMS 2.0.7. The listing is for web applications and provides code defenders can use to reproduce the issue. No exploitation in the wild or CVE assignment is stated in the listing.

Exploit-DB · 19d agoExploit / PoC

Related CVEs

  • Unauthenticated Takeover of Oracle E-Business Suite Concurrent Processing
    CVE-2025-61882 is a critical (CVSS 9.8) authentication flaw (CWE-287) in the BI Publisher Integration component of the Oracle Concurrent Processing product within Oracle E-Business Suite. An unauthenticated attacker with network access over HTTP can exploit it remotely with no credentials and no user interaction, achieving a takeover of Oracle Concurrent Processing with high confidentiality, integrity, and availability impact. Any organization running Oracle E-Business Suite 12.2.3 through 12.2.14 is affected, especially instances reachable from the internet. The flaw is being actively exploited in the wild: the Cl0p data-theft group has used it to breach dozens of organizations (including Harvard University, with 1.3 TB of data leaked), CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06 with known ransomware use, and EPSS puts its 30-day exploitation probability at 99.7%.
    · Oracle E-Business Suite (Oracle Concurrent Processing, BI Publisher Integration component) 12.2.3 - 12.2.14 KEV ransomwarelarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.